mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf 1/1] bpf, riscv: Fix stack arguments of struct_ops trampolines
@ 2026-10-01 15:40 KaFai Wan
  2026-10-02  1:13 ` KaFai Wan
  0 siblings, 1 reply; 2+ messages in thread
From: KaFai Wan @ 2026-10-01 15:40 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
	Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
	Ihor Solodrai, Björn Töpel, Pu Lehui, Puranjay Mohan,
	Paul Walmsley, Palmer Dabbelt, Albert Ou, Alexandre Ghiti, bpf,
	linux-riscv, linux-kernel
  Cc: KaFai Wan

When a struct_ops trampoline takes more than 8 arguments (up to 12), the
9th and beyond are passed on the stack. store_args() copies them into the
trampoline frame using a hard-coded FP + 16 base:

	emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);

That offset only holds for fentry trampolines, where the traced function's
T0/FP are saved at FP - 8/FP - 16 and its stack arguments start at FP + 16.
A struct_ops trampoline is called directly, so its stack arguments start at
FP + 0 and store_args() reads the wrong words. BPF programs then see garbage
for arg9 and beyond, which fails the selftest:

  struct_ops_multi_args/test_trampoline_stack_args:FAIL

Pass the stack argument base offset to store_args(): 0 for struct_ops
trampolines, 16 otherwise.

Fixes: 6801b0aef79d ("riscv, bpf: Add 12-argument support for RV64 bpf trampoline")
Signed-off-by: KaFai Wan <kafai.wan@linux.dev>
---
 arch/riscv/net/bpf_jit_comp64.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/arch/riscv/net/bpf_jit_comp64.c b/arch/riscv/net/bpf_jit_comp64.c
index 01fe66774f02..4ae6674f58ed 100644
--- a/arch/riscv/net/bpf_jit_comp64.c
+++ b/arch/riscv/net/bpf_jit_comp64.c
@@ -875,7 +875,7 @@ int bpf_arch_text_poke(void *ip, enum bpf_text_poke_type old_t,
 	return ret;
 }
 
-static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ctx)
+static void store_args(int nr_arg_slots, int args_off, int stack_base, struct rv_jit_context *ctx)
 {
 	int i;
 
@@ -883,8 +883,7 @@ static void store_args(int nr_arg_slots, int args_off, struct rv_jit_context *ct
 		if (i < RV_MAX_REG_ARGS) {
 			emit_sd(RV_REG_FP, -args_off, RV_REG_A0 + i, ctx);
 		} else {
-			/* skip slots for T0 and FP of traced function */
-			emit_ld(RV_REG_T1, 16 + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
+			emit_ld(RV_REG_T1, stack_base + (i - RV_MAX_REG_ARGS) * 8, RV_REG_FP, ctx);
 			emit_sd(RV_REG_FP, -args_off, RV_REG_T1, ctx);
 		}
 		args_off -= 8;
@@ -1179,7 +1178,8 @@ static int __arch_prepare_bpf_trampoline(struct bpf_tramp_image *im,
 	func_meta = nr_arg_slots;
 	emit_store_stack_imm64(RV_REG_T1, -func_meta_off, func_meta, ctx);
 
-	store_args(nr_arg_slots, args_off, ctx);
+	/* skip slots for T0 and FP of traced function */
+	store_args(nr_arg_slots, args_off, is_struct_ops ? 0 : 16, ctx);
 
 	if (bpf_fsession_cnt(tnodes)) {
 		/* clear all session cookies' value */
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-02  1:13 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01 15:40 [PATCH bpf 1/1] bpf, riscv: Fix stack arguments of struct_ops trampolines KaFai Wan
2026-10-02  1:13 ` KaFai Wan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®